vendor:
Sami FTP Server
by:
Critical Security research
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Sami FTP Server
Affected Version From: 2.0.1
Affected Version To: 2.0.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2, Windows XP SP0, FreeBSD 6.0-RELEASE Wine 0.9.6
Sami FTP Server v2.0.1 Remote notepad.exe execution PoC
This is a proof-of-concept exploit for the Sami FTP Server v2.0.1. It allows for the remote execution of the notepad.exe executable on the target system. The exploit has been tested on Windows XP SP2, Windows XP SP0, and FreeBSD 6.0-RELEASE Wine 0.9.6. The exploit uses the Net::FTP module in Perl and allows for the execution of arbitrary code on the target system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the Sami FTP Server or switch to a different FTP server software. Additionally, it is recommended to regularly update and patch the operating system and other software on the target system.